Data Processing Agreement
Our commitments regarding data processing, privacy safety controls, and compliance guidelines.
1. Scope and Object of the Processing
This Data Processing Agreement ("DPA") applies to the processing of personal data by MXend on behalf of our customer (the "Data Controller") as part of the secure email services provided under our Terms of Service.
2. Obligations of Processor
MXend (the "Data Processor") agrees and covenants to:
- Process personal data only on documented instructions from the Data Controller, including with respect to transfers of personal data to a third country or an international organization.
- Ensure that persons authorized to process the personal data have committed themselves to confidentiality or are under an appropriate statutory obligation of confidentiality.
- Take all security measures required pursuant to Article 32 of the GDPR to ensure the security, integrity, and resilience of our processing systems.
3. Sub-Processors
The Controller grants a general authorization to the Processor to engage sub-processors. The Processor shall inform the Controller of any intended changes concerning the addition or replacement of sub-processors, thereby giving the Controller the opportunity to object to such changes.
4. Data Subject Rights
Taking into account the nature of the processing, the Processor shall assist the Controller by appropriate technical and organizational measures, insofar as this is possible, for the fulfillment of the Controller's obligation to respond to requests for exercising the data subject's rights.